CVE-2026-101898: Axios
High severity, CVSS 7.0. EPSS: 0.5% chance of exploitation in the next 30 days.
Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy. An HTTPS request uses httpVersion: 2 with explicit config.proxy or environment-derived proxy settings, or relies on caller-supplied config.lookup DNS policy. The HTTP/2 path can connect without the configured proxy behavior or without applying the caller-supplied config.lookup policy before http2.connect(). Requests can bypass the intended proxy route or the caller-supplied DNS resolution policy. This issue is fixed in version 1.20.0.
Affected products
- Axios Axios: from 1.13.0, before 1.20.0 (fixed in 1.20.0)
Published 2026-09-28. Last modified 2026-09-30.